# BinSoft mpGabinet RCE via chained authentication bypass

Published: 2026-04-28 · Severity: critical
Canonical: https://vorant.io/reports/5e7a2ff3-771f-5dfc-b520-5c5f3072ad6a/binsoft-mpgabinet-rce-via-chained-authentication-bypass

> Three vulnerabilities in BinSoft mpGabinet enable unauthenticated RCE by chaining excessive database privileges, client-side authentication bypass, and malicious attachment execution.

CERT Polska disclosed three vulnerabilities in BinSoft mpGabinet software affecting version 23.12.19 and earlier. CVE-2026-40550 exposes administrative database credentials in application memory due to excessive privilege assignment. CVE-2026-40551 allows authentication bypass through client-side verification manipulation. CVE-2026-40552 enables remote command execution when an authenticated user modifies attachment paths in the database to reference attacker-controlled network resources.

The critical risk emerges from chaining all three flaws: an unauthenticated attacker can extract database credentials from memory, bypass authentication to access any account, manipulate attachment references in the database, and achieve system-level command execution when a user opens the malicious attachment. The vulnerabilities stem from fundamental design weaknesses including client-side security controls and overprivileged database access.

The disclosure follows responsible coordinated vulnerability reporting by security researchers Robert Kruczek and Kamil Szczurowski. Organizations running affected mpGabinet versions should prioritize patching, as the exploitation chain requires no special privileges and can be executed remotely by unauthenticated attackers.

## Mentioned in this report

- Vulnerabilities: CVE-2026-40550, CVE-2026-40551, CVE-2026-40552

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-40550

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5e7a2ff3-771f-5dfc-b520-5c5f3072ad6a/binsoft-mpgabinet-rce-via-chained-authentication-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
